i am a beginner in using splunk. I'm doing research on log traffic from Palo Alto. inside i upload data to splunk. what is the most appropriate sourcetype for me to choose?
you are probably using this app: Palo Alto Networks App for Splunk and add-on Palo Alto Networks Add-on for Splunk for getting logs in. Just look from App's instruction how to use it. I think that most sourcetypes are named like pan:xxx
View solution in original post